Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

Move to phishing-resistant authentication before SMS and voice retire We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication. Passkeys are becoming the default authentication experience in Microsoft Entra, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027.

For more context on why Microsoft is moving to phishing-resistant authentication by default, please read our Microsoft Security Blog announcement. What is changing Passkeys become the default authentication experience for users currently enabled for SMS or voice.Microsoft-provided telecom delivery for SMS and voice will be retired. Customer-managed telecom providers configured through the Microsoft Security Store are not affected. Why this is changing SMS and voice are among the most vulnerable authentication methods available today and provide significantly weaker protection against phishing, SIM-swap, and replay attacks than passkeys. Moving to phishing-resistant methods gives your organization stronger security by default. Impact on you and key dates September 1, 2026 — Users enabled for SMS or voice are automatically enabled for passkeys and will be nudged to register a passkey when they next complete MFA. (If you do not want this, move users out of SMS or voice in the Authentication Methods Policy before this date.)February 1, 2027 — Microsoft-provided SMS and voice are fully retired in Microsoft Entra ID. Customer-managed telecom providers are unaffected.After February 1, 2027 — Users whose only available MFA method is SMS or voice will receive a blocking prompt to register a passkey before they can continue signing in. There is no opt out from this enforcement; it applies to all tenants. If no users in your tenant are enabled for SMS or voice, no action is required and you can disregard the steps below.

If you do have users enabled for SMS or voice, the required action is to move every one of those users off SMS and voice before February 1, 2027. Microsoft recommends passkeys — the default phishing-resistant credential in Microsoft Entra ID. Take the following steps: Find affected users. Identify who in your tenant is still enabled for SMS or voice. Move users to passkeys. Enable passkeys and run a registration campaign to drive adoption at scale before auto-enablement on September 1, 2026. Communicate the change. Notify your users of what is changing, when, and the action they need to take. Evaluate a telecom provider only if required. If you have a regulatory or operational need to keep SMS or voice, configure a customer-managed provider through the Microsoft Security Store before February 1, 2027 (provider options and pricing published beginning September 18, 2026; configuration available beginning October 30, 2026). The bottom line: every SMS and voice user must be on a phishing-resistant method — passkeys are recommended — before Microsoft-provided SMS and voice retire on February 1, 2027. Acting before September 1, 2026 lets you move users on your own schedule and avoid blocking prompts.        Read migration guidance >       

You Really Don’t Want This Delivery

The NJCCIC observed a phishing campaign impersonating UPS delivery notifications. These messages use subject lines such as “Parcel Arrival Notification,” “Your Package Is Ready for Pickup,” and “Your Parcel Has Arrived” and are purported to be from the following sender(s):
“UPS Parcel Services” <contact[@]shipfasts[.]com> “UPS Delivery Support” <contact[@]learnstax[.]com>
Messages include an Adobe PDF attachment that uses UPS branding and the UPS logo to appear legitimate. They claim the user needs to update Adobe Flash Reader to view the file. Clicking the download button triggers a Visual Basic Script (VBScript) to download and run. The script executes a curl command to download the Microsoft Installer (MSI) package for installing ScreenConnect. This setup enables autorun at Windows startup. After installation, a benign PDF is displayed to the user.

Beware of Threat Actors Targeting IT Help Desk Staff

Information technology (IT) help desk staff are heavily targeted because they often possess privileged administrative rights and provide an entry point for account recovery, such as resetting passwords and bypassing multi-factor authentication (MFA). To identify high-value targets, threat actors perform reconnaissance on corporate websites, networking platforms such as LinkedIn, or social media websites. They pose as legitimate employees and use voice phishing (vishing) in their social engineering attacks to trick internal or outsourced IT help desk staff into bypassing controls. Vishing, which has surged significantly over the past several years, combined with publicly available information and artificial intelligence (AI), enables threat actors to increasingly impersonate legitimate employees, clone voices, and create audio deepfakes.
In IT help desk schemes, threat actors claim they were locked out of their account, could not access their authenticator, lost their phone, or damaged their laptop. They may also create urgent or stressful scenarios, such as a business meeting starting shortly or an employee traveling on business, and request immediate access to the account. Once threat actors convince the IT help desk staff to reset the password or disable the original MFA token, they can register their own device, granting them complete, legitimate access to the network. Prominent and aggressive threat actors, such as Scattered Spider and O-UNC-034, have posed as employees or traveling executives to initiate account takeovers. Their main goal is to infiltrate networks, establish persistence, move laterally to critical assets, access internal applications or cloud services, exfiltrate data, and deploy ransomware.
The NJCCIC received a report of threat actors impersonating an employee of a New Jersey organization and contacting the organization’s outsourced IT help desk to reset their password. The IT help desk staff bypassed established procedures, reset the password, and set up the corporate app on the device. The threat actors then accessed the account and changed the impersonated employee’s bank account information for direct deposit to a threat actor-controlled account.

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution – PATCH NOW

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

THREAT INTELLIGENCE:
There are currently no reports of these vulnerabilities being exploited in the wild.

SYSTEMS AFFECTED:

  • Chrome prior to 151.0.7922.108/.109 for Windows and Mac
  • Chrome prior to 151.0.7922.108 for Linux



RISK:
Government:

  • Large and medium government entities: Medium
  • Small government entities: Medium



Businesses:

  • Large and medium business entities: Medium
  • Small business entities: Medium



Home users: Low

TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Details of these vulnerabilities are as follows:

TacticInitial Access (TA0001):
TechniqueDrive-By Compromise (T1189):

  • Use after free in WebGL (CVE-2026-19137, CVE-2026-19170)
  • Use after free in Aura (CVE-2026-19149, CVE-2026-19147)
  • Use after free in Skia (CVE-2026-19154, CVE-2026-19176)
  • Out of bounds write in ANGLE (CVE-2026-19157)
  • Use after free in Views (CVE-2026-19172, CVE-2026-19142, CVE-2026-19158, CVE-2026-19159)
  • Insufficient validation of untrusted input in Contextual Tasks (CVE-2026-19169)
  • Inappropriate implementation in V8 (CVE-2026-19168, CVE-2026-19150)
  • Heap buffer overflow in CrashReporting (CVE-2026-19138)
  • Race in CredentialProvider (CVE-2026-19139)
  • Use after free in GPU (CVE-2026-19140)
  • Use after free in Resources (CVE-2026-19141)
  • Insufficient validation of untrusted input in WebAPKs (CVE-2026-19143)
  • Use after free in HTML (CVE-2026-19144)
  • Use after free in Translate (CVE-2026-19145)
  • Uninitialized Use in GPU (CVE-2026-19146)
  • Out of bounds write in GPU (CVE-2026-19148)
  • Use after free in V8 (CVE-2026-19151)
  • Inappropriate implementation in Navigation (CVE-2026-19152)
  • Insufficient validation of untrusted input in Workers (CVE-2026-19153)
  • Use after free in Payments (CVE-2026-19155, CVE-2026-19175)
  • Heap buffer overflow in Base (CVE-2026-19156)
  • Uninitialized Use in Skia (CVE-2026-19160, CVE-2026-19161)
  • Out of bounds write in V8 (CVE-2026-19162)
  • Use after free in Media (CVE-2026-19163, CVE-2026-19171)
  • Insufficient validation of untrusted input in Codecs (CVE-2026-19164)
  • Use after free in Extensions (CVE-2026-19165)
  • Use after free in Web Authentication (CVE-2026-19166)
  • Integer overflow in GPU (CVE-2026-19167)
  • Out of bounds write in Skia (CVE-2026-19173)
  • Integer overflow in V8 (CVE-2026-19174)
  • Insufficient validation of untrusted input in UI (CVE-2026-19177)



Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

RECOMMENDATIONS:
We recommend the following actions be taken:

  • Apply appropriate updates provided by Google to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
    • Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
    • Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
    • Safeguard 9.1: Ensure Use of Only Fully Supported Browsers and Email Clients: Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.
  • Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026: Privileged Account Management)
    • Safeguard 4.7: Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
    • Safeguard 5.4: Restrict Administrator Privileges to Dedicated Administrator Accounts: Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.
  • Restrict execution of code to a virtual environment on or in transit to an endpoint system. (M1048: Application Isolation and Sandboxing)
  • Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050: Exploit Protection)
    • Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
  • Restrict use of certain websites, block downloads/attachments, block Javascript, restrict browser extensions, etc. (M1021: Restrict Web-Based Content)
    • Safeguard 9.2: Use DNS Filtering Services: Use DNS filtering services on all enterprise assets to block access to known malicious domains.
    • Safeguard 9.3: Maintain and Enforce Network-Based URL Filters: Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise assets.
    • Safeguard 9.6: Block Unnecessary File Types: Block unnecessary file types attempting to enter the enterprise’s email gateway.
  • Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from un-trusted sources. Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources. (M1017: User Training)
    • Safeguard 14.1: Establish and Maintain a Security Awareness Program: Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.
    • Safeguard 14.2: Train Workforce Members to Recognize Social Engineering Attacks: Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.
      ​​​​


REFERENCES:

Google:
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01193673229.html

CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19137
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19138
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19139
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19140
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19141
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19142
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19143
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19144
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19145
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19146
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19147
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19148
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19149
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19150
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19151
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19152
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19153
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19154
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19155
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19156
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19157
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19158
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19159
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19160
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19161
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19162
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19163
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19164
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19165
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19166
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19167
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19168
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19169
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19170
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19171
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19172
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19173
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19174
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19175
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19176
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19177

New Standards Will Protect Encryption From Quantum Computers

From our bank accounts to smartphones, all our sensitive data and devices are protected with a technology known as cryptography.

Present-day cryptography essentially uses a very challenging set of math problems that are nearly impossible for current computers to solve. These math problems act as a “lock” to keep hackers or spies away from the personal information in your “house.”

But experts are working to develop specialized machines known as quantum computers. Quantum computers have incredible potential to do tasks that current computers struggle with, such as discovering new medications.

The downside is that they may also have the potential to thwart today’s cryptography. Sufficiently powerful versions of these machines could put all our personal information, financial transactions, and business and government secrets at risk.

READ MORE

Announcing Final NIST Transit CSF Community Profile + Upcoming Webinar

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the final NIST Interagency Report 8576, Transit Cybersecurity Framework Community Profile, to help U.S. transit agencies strengthen their cybersecurity practices while supporting safe and resilient transit services.

Additionally, the NCCoE is hosting a virtual event on September 1, 2026 to discuss the Profile. Register today to reserve your spot and discover how the Transit Cybersecurity Framework (CSF) Community Profile can support your agency’s cybersecurity efforts.

Background

Transit agencies operate a complex network of business and operational technology (OT) systems to fulfill their mission. As these systems increasingly rely on digital, network-based communication, the cyberattack surface has expanded, requiring agencies to manage cybersecurity risks alongside safety and operational priorities.

Developed in collaboration with transit agencies, federal agencies involved in transit, and other stakeholders, the Transit CSF Community Profile provides a voluntary, risk-based resource to help transit agencies strengthen cybersecurity preparedness and resilience against evolving threats facing the sector.

The Transit CSF Community Profile focuses on three strategic priorities:

  1. Securing and managing critical assets to support safe and reliable operations.
  2. Strengthening collaboration with stakeholders and suppliers to improve resilience and supply chain security.
  3. Continuously improving organizational operations and processes, workforce cybersecurity awareness, and capabilities.

The Profile helps transit agencies prioritize cybersecurity activities that align with their mission by mapping them to NIST Cybersecurity Framework (CSF) 2.0 outcomes and relevant industry guidelines and considerations.

Download the final Transit CSF Community Profile today to learn how it can support your organization’s cybersecurity efforts!

Upcoming Project Webinar

Join the NIST National Cybersecurity Center of Excellence (NCCoE) on September 1, 2026 at 2:00 P.M. EDT for a virtual event and panel discussion to learn more about the final Profile. Hear transit operators share their perspectives on the Profile and discuss how transit agencies can use it to strengthen cybersecurity and support safe, reliable, and resilient transit operations.

Visit the event page and register today!

View the Profile 

Upcoming Webinar: Foundational Cybersecurity for Small Businesses

Date: August 20, 2026

Time: 2:00 p.m.- 3:00 p.m. EDT

Description:

The small business community is a large portion of the U.S. and global economy and is also largely under-resourced when it comes to building strong cyber defenses. The efficient use, or prioritization, of limited resources is critical. Speakers from the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Institute of Standards and Technology (NIST) will share how to identify cybersecurity risks that small businesses commonly face and will share practical and actionable cybersecurity safeguards that can significantly reduce cybersecurity risks and that typically do not take significant time, financial investment, or technical expertise to implement.

Ample time will be saved for audience questions and discussion.

Speakers:

  • Colleen P. Ferranti, Assistant Section Chief, Cyber Engagement & Intelligence Section, Federal Bureau of Investigation (FBI)
  • Christine Serrano Glassner, Chief External Affairs Officer, Cybersecurity and Infrastructure Security Agency (CISA)
  • Daniel Eliot, Lead for Small Business Engagement, National Institute of Standards and Technology (NIST)
Register Here

CISA, FBI, and Partners Release Joint Cybersecurity Advisory on Gunra Ransomware

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), in collaboration with U.S. government and international partners, released a joint Cybersecurity Advisory, #Stopransomware: Gunra Ransomware, part of an ongoing series detailing ransomware variants and threat actors. This joint advisory provides technical details on Gunra activity, along with detection and mitigation guidance to help protect at-risk organizations across government and critical infrastructure.

Gunra first emerged in April 2025 and expanded to a formal ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums. Gunra actors use a double-extortion model, meaning actors both encrypt and exfiltrate sensitive data to create two forms of leverage for collecting ransom payments. They demand ransom via a Tor network-based negotiation portal and threaten to publish stolen data on their dedicated leak site (DLS) if victim organizations do not pay within five to seven days. As part of the 2026 expansion, Gunra actors have adopted branding aliases (including Golden Community) and further commercialized by actively recruiting penetration testers and ethical hackers as initial access brokers in exchange for a share of ransom profits. They have also demonstrated the ability to disable backup features, and in one instance, prevented restoration by deleting backup and archived data stored at both a primary data center and disaster recovery center. Victim organizations listed on Gunra’s DLS site are from multiple sectors across the world.

CISA, the FBI, and authoring agencies urge organizations to implement the advisory’s mitigations, including the following key actions:

  • Prioritize patching known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure.
  • Implement and test offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without ransom payment.
  • Segment networks to restrict lateral movement from an initially compromised device to other systems in the organization.

Read the full advisory for more information on how to protect your organization from Gunra.